Tenable Network Security Podcast - Episode 57 - Dennis Brown
Welcome to the Tenable Network Security Podcast - Episode 57
Hosts: Paul Asadoorian, Product Evangelist
Interview with Dennis Brown
"Dennis Brown is a research engineer for Tenable Network Security. He specializes in malware analysis with a penchant for botnet research. Dennis has spoken previously at Defcon 18, Toorcon 10 and 11 and on the PaulDotCom security podcast. He also organizes the DC401 hacker group in Rhode Island and the QuahogCon security conference."
Dennis recently gave a presentation titled "Resilient Botnet Command and Control with Tor" at HiTB Malaysia and Toorcon 13. Dennis and I discussed the following topics:
- I was working for a University when Tor first became popular. This presented many challenges; students were using it to evade detection by the RIAA/MPAA, attackers were using it to launch attacks against us, and I even encountered a few Tor exit nodes in my time. How has the Tor network evolved over time?
- Which botnets have been observed in the wild using Tor?
- What is a private Tor network? How do you build a private Tor network? Is it easy?
- How does using Tor affect speed? Does this impact the botnet, and how so?
- What is an HTTP hidden service? Tor3web proxy? How does this all work to mask the botnet's command and control channel?
- I always thought that encryption would be the end of the good guys' fight against malware, but has that largely turned out not to be true or has it?
- It seems that masking the command and control channel produces the highest rate of success for a botnet. How does Tor help the bad guys accomplish this?
- How can we detect botnets using Tor?